Skip to content

Failing PyNaCl and cryptography Packages #271

Description

@demoutrei

I'm building a side-project that implements workers-py together with Discord Interaction API, i.e. conjuring an HTTP-interaction (serverless) Discord app.

A prerequisite, crucial step in doing so is to validate security headers, and the package I (mainly wanna) use is PyNaCl. However, running the wrangler locally raises an error.

An alternative can also be (perhaps) done with the cryptography package, and, yet again, as well raises an error---albeit different.

Prerequisites

Python version: 3.14

OS: W10

Packages: pynacl, and (separately) cryptography

PyNaCl

Steps to Reproduce

  1. Install pynacl package.

  2. In any of the Python files, typically entry.py, import nacl.signing.VerifyKey and nacl.exceptions.BadSignatureError---the necessary imports for the prerequisite step.

from nacl.signing import VerifyKey
from nacl.exceptions import BadSignatureError
  1. Run the project locally: uv run pywrangler dev.

  2. There is no further step here as the raised error originates from the import lines.

Full Code

from nacl.exceptions import BadSignatureError
from nacl.signing import VerifyKey
from workers import Response, WorkerEntrypoint

class Default(WorkerEntrypoint):
  async def fetch(self, request):
    if request.method != "POST": return Response("Method Not Allowed", status = 405)
    signature = request.headers["X-Signature-Ed25519"]
    timestamp = request.headers["X-Signature-Timestamp"]
    if not signature or not timestamp: return Response("Unauthorized", status = 401)
    body = await request.text()
    try:
      verify_key = VerifyKey(bytes.fromhex(self.env.APPLICATION_PUBLIC_KEY))
      verify_key.verify(f"{timestamp}{body}".encode(), bytes.fromhex(signature))
    except BadSignatureError: return Response("Invalid request signature", status = 401)

Raised Exception

[ERROR] service core:user:discord-http: Uncaught Error: PythonError: Traceback (most recent call last):

  File "/lib/python314.zip/_pyodide/_base.py", line 666, in pyimport_impl
    res = __import__(stem, fromlist=fromlist)
  File "/session/metadata/entry.py", line 1, in <module>
    from nacl.signing import VerifyKey
  File "/session/metadata/python_modules/nacl/signing.py", line 16, in <module>
    import nacl.bindings
  File "/session/metadata/python_modules/nacl/bindings/__init__.py", line 16, in <module>
    from nacl.bindings.crypto_aead import (
    ...<42 lines>...
    )
  File "/session/metadata/python_modules/nacl/bindings/crypto_aead.py", line 17, in <module>
    from nacl._sodium import ffi, lib
ImportError: could not load dynamic lib: /session/metadata/python_modules/nacl/_sodium.abi3.so
Error: Internal Emscripten code tried to eval, this should not happen, please file a bug report

  at null.<anonymous> (pyodideRuntime-internal:emscriptenSetup:21276:12) in new_error
  at [object Object] in $wrap_exception
  at [object Object] in $pythonexc2js
  at null.<anonymous> (pyodideRuntime-internal:emscriptenSetup:24011:97) in
callPyObjectKwargsPromising


[ERROR] The Workers runtime failed to start. There was likely a problem with the workerd binary or your configuration.

Runtime stderr:
{"timestamp":"1790003442912","level":"error","source":"src/workerd/server/json-logger.c++:127","message":"service
core:user:discord-http: Uncaught Error: PythonError: Traceback (most recent call last):\n  File
\"/lib/python314.zip/_pyodide/_base.py\", line 666, in pyimport_impl\n    res = __import__(stem,
fromlist=fromlist)\n  File \"/session/metadata/entry.py\", line 1, in <module>\n    from
nacl.signing import VerifyKey\n  File \"/session/metadata/python_modules/nacl/signing.py\", line
16, in <module>\n    import nacl.bindings\n  File
\"/session/metadata/python_modules/nacl/bindings/__init__.py\", line 16, in <module>\n    from
nacl.bindings.crypto_aead import (\n    ...<42 lines>...\n    )\n  File
\"/session/metadata/python_modules/nacl/bindings/crypto_aead.py\", line 17, in <module>\n    from
nacl._sodium import ffi, lib\nImportError: could not load dynamic lib:
/session/metadata/python_modules/nacl/_sodium.abi3.so\nError: Internal Emscripten code tried to
eval, this should not happen, please file a bug report\n\n  at
pyodideRuntime-internal:emscriptenSetup:21276:12 in new_error\n  at wasm://wasm/0249d42a:1:415075
in $wrap_exception\n  at wasm://wasm/0249d42a:1:415275 in $pythonexc2js\n  at
pyodideRuntime-internal:emscriptenSetup:24011:97 in
callPyObjectKwargsPromising","context_depth":0}

cryptography

Steps to Reproduce

  1. Install cryptography package.

  2. In any of the Python files, typically entry.py, import Ed25519PublicKey and InvalidSignature.

from cryptography.exceptions import InvalidSignature
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey
  1. Run the project locally: uv run pywrangler dev.

Full Code

from cryptography.exceptions import InvalidSignature
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PublicKey
from workers import Response, WorkerEntrypoint

class Default(WorkerEntrypoint):
  async def fetch(self, request):
    if request.method != "POST": return Response("Method Not Allowed", status = 405)
    signature = request.headers["X-Signature-Ed25519"]
    timestamp = request.headers["X-Signature-Timestamp"]
    if not signature or not timestamp: return Response("Unauthorized", status = 401)
    body = await request.text()
    try:
      verify_key = Ed25519PublicKey.from_public_bytes(bytes.fromhex(self.env.APPLICATION_PUBLIC_KEY))
      verify_key.verify(f"{timestamp}{body}".encode(), bytes.fromhex(signature))
    except InvalidSignature: return Response("Invalid request signature", status = 401)

Raised Exception

ERROR    Error running command: uv.EXE pip compile C:\Users\demoutrei\Documents\discord-http\pyproject.toml                                     
         C:\Users\DEMOUT~1\AppData\Local\Temp\tmp1nvg11gw.txt --python cpython-3.14.2-emscripten-wasm32-musl --extra-index-url                  
         https://index.pyodide.org/314.0.7 --index-strategy unsafe-best-match --no-header -o                                                    
         C:\Users\demoutrei\Documents\discord-http\pylock.toml --no-build                                                                       
         Exit code: 1                                                                                                                           
         Output:                                                                                                                                
         error: No solution found when resolving dependencies                                                                                   
           cause: Because cryptography==50.0.1 has no usable wheels and only cryptography<=50.0.1 is available, we can conclude that            
         cryptography>=50.0.1 cannot be used.                                                                                                   
                  And because discord-http depends on cryptography>=50.0.1, we can conclude that your requirements are unsatisfiable.           
                                                                                                                                                
         hint: Wheels are required for `cryptography` because building from source is disabled for all packages (i.e., with `--no-build`)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions